Cyber attack causes mass global disruption

Companies and entities around the world are contending with a new cyber attack that caused severe damage. 

A new and highly virulent outbreak of malicious data-scrambling software is causing mass disruption across the world, hitting companies and governments in Europe especially hard.

Officials in Ukraine reported serious intrusions of the country’s power grid as well as at banks and government offices, where one senior executive posted a photo of a darkened computer screen and the words, “the whole network is down.” The prime minister cautioned that the country’s “vital systems” hadn’t been affected.

Russia’s Rosneft oil company also reported falling victim to hacking and said it had narrowly avoided major damage, as did Danish shipping giant A.P. Moller-Maersk.

“We are talking about a cyber attack,” said Anders Rosendahl, a spokesman for the Copenhagen-based shipping group. “It has affected all branches of our business, at home and abroad.”

The attack was confirmed to have spread beyond Europe when US drugmaker Merck, based in New Jersey, said its systems had also been compromised.

A Ransomware Campaign

The number of companies and agencies reportedly affected by the ransomware campaign was piling up fast, and the electronic rampage appeared to be rapidly snowballing into a worldwide crisis.

Read  Israel's top security agency failing to protect PM from protesters, minister accuses

There’s very little information about what might be behind the disruption at each specific company, but cyber-security experts rapidly zeroed in on a form of ransomware, the name given to programs that hold data hostage by scrambling it until a payment is made.

“A massive ransomware campaign is currently unfolding worldwide,” said Romanian cyber-security company Bitdefender, where analyst Bogdan Botezatu said it appeared to be nearly identical to GoldenEye, one of a family of hostage-taking programs that has been circulating for months. Some analysts were calling the new form of ransomware Petya.

It’s not clear whether or why the ransomware has suddenly become so much more potent, but Botezatu said that it was likely spreading automatically across a network, without the need for human interaction. Such self-spreading software, often called “worms,” is particularly feared because it can replicate rapidly, like a contagious disease.

“It’s like somebody sneezing into a train full of people,” Botezatu told the Associated Press. “You just have to exist there and you’re vulnerable.”

The world is still recovering from a previous outbreak of ransomware, called WannaCry or WannaCrypt, which spread rapidly using digital break-in tools originally created by the US National Security Agency and recently leaked to the web.

“Data breaches and cyber hacks are one of the biggest risks facing business worldwide,” said Michelle Crorie, a partner at law firm Clyde & Co. who specializes in cyber-security issues. “The WannaCry attack and now Petya clearly demonstrate that hackers do not discriminate which type of business they are targeting.”

This particular variant of ransomware leaves a message with a contact email; several messages sent to the address were not immediately returned.

Israel in Constant Battle

Just yesterday, Nadav Argaman, the Shin Bet head, said his agency has gone on the offensive against hackers trying to carry out cyber-attacks against Israel.

He said that “passive defense” is not enough, and that the Shin Bet studied hackers’ strategies and developed “a variety of ways and methods” on how to strike back.

Israel is considered a global leader in the cyber security business.

By: AP